The devices do not implement any authentication for the web interface or the MQTT server. An attacker who has network access to the device immediately gets administrative access to the devices and can perform arbitrary administrative actions and reconfigure the devices or potentially gain access to sensitive data.
References
Link | Resource |
---|---|
https://r.sec-consult.com/echarge |
Configurations
No configuration.
History
21 May 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
21 May 2025, 12:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-21 12:16
Updated : 2025-05-21 20:24
NVD link : CVE-2025-27803
Mitre link : CVE-2025-27803
CVE.ORG link : CVE-2025-27803
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function